Background: I have three entities (language: JS):
- Client on Browser
- Google Cloud Functions
- An HTTP Server [Have Firebase admin Auth middleware]
So, From 1 and 2, I want to communicate with 3 using HTTPS calls. Because the 3 has admin Auth already, I am able to authorize the calls from clients(1).
But I want to know how I can authorize calls from google cloud functions(2) so that I can securely communicate with both entities.
Token Auth Middleware:
const validateFirebaseIdToken = async (req: any, res: any, next: any) => {
console.log(await auth.getCredentials());
if (
(!req.headers.authorization ||
!req.headers.authorization.startsWith("Bearer ")) &&
!(req.cookies && req.cookies.__session)
) {
console.log(
"No Firebase ID token was passed as a Bearer token in the Authorization header." +
"Make sure you authorize your request by providing the following HTTP header:" +
"Authorization: Bearer <Firebase ID Token>" +
'or by passing a "__session" cookie.'
);
res.status(403).send("Unauthorized 1");
return;
}
let idToken;
if (
req.headers.authorization &&
req.headers.authorization.startsWith("Bearer ")
) {
console.log('Found "Authorization" header');
// Read the ID Token from the Authorization header.
idToken = req.headers.authorization.split("Bearer ")[1];
} else if (req.cookies) {
console.log('Found "__session" cookie');
// Read the ID Token from cookie.
idToken = req.cookies.__session;
} else {
// No cookie
res.status(403).send("Unauthorized 2");
return;
}
try {
const decodedIdToken = await admin.auth().verifyIdToken(idToken);
req.user = decodedIdToken;
next();
return;
} catch (error) {
console.log("Error while verifying Firebase ID token:" + error);
res.status(403).send("Unauthorized 3");
return;
}
};